1 Feb 2008 01:17
Re: [OpenID] A couple of questions regarding OpenID...
Eddy Nigg (StartCom Ltd. <eddy_nigg <at> startcom.org>
2008-02-01 00:17:35 GMT
2008-02-01 00:17:35 GMT
Per Ekström wrote:
There are however secure methods for authentication other than user/pass pairs and OpenID has an draft extension for this: http://openid.net/specs/openid-provider-authentication-policy-extension-1_0-01.html
I guess that's correct, as with anything that uses a user name and password for authentication. There is no difference of a phishing attempt of an online banking web site and an IDP, with different results perhaps. Phishing of banking sites will cost somebody money, whereas with OpenID it might be used for spamming and identity theft (whatever that implies).
My first question is regarding the Phishing attacks that are mentioned at Wikipedia [1] - Are they still valid or is it just FUD that has been floating around since an old version of the standard?
There are however secure methods for authentication other than user/pass pairs and OpenID has an draft extension for this: http://openid.net/specs/openid-provider-authentication-policy-extension-1_0-01.html
The RP can require SSL of only known CAs. This should solve this concern mostly. But the provider will not send the authentication bits in any case, in most cases only a yes/no/cancel reply.
And second - While I know Man-In-The-Middle between user and OpenID-provider is quite easy to stave off, what about OpenID-provider and the website I'm trying to log in to? Whenever man-in-the-middle discussion about this appears, it's always in the form of User-to-OpenID-Provider, not the other way around.
--
| Regards | |
| Signer: | Eddy Nigg, StartCom Ltd. |
| Jabber: | startcom <at> startcom.org |
| Blog: | Join the Revolution! |
| Phone: | +1.213.341.0390 |
_______________________________________________ general mailing list general <at> openid.net http://openid.net/mailman/listinfo/general
RSS Feed